CVE-2022-46597: OS Command Injection
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sysservice parameter in the setupwizardmydlink (sub4104B8) function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-46597?
CVE-2022-46597 refers to a command injection vulnerability found in TRENDnet TEW755AP 1.13B01 firmware via the sys_service parameter in the setup_wizard_mydlink function.
How severe is CVE-2022-46597?
CVE-2022-46597 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2022-46597?
TRENDnet TEW755AP firmware version 1.13B01 is affected by CVE-2022-46597.
How can I fix CVE-2022-46597?
To fix CVE-2022-46597, it is recommended to update to a patched version of the firmware provided by the vendor.
Where can I find more information about CVE-2022-46597?
You can find more information about CVE-2022-46597 at the following reference: [link](https://brief-nymphea-813.notion.site/Vul1-TEW755-command-injection-setup_wizard_mydlink-dccea20f75e04110878213126612feba).